Executive brief
Google Chrome is a widely used web browser. A vulnerability in how the browser handles CSS (Cascading Style Sheets) could allow a remote attacker to trick users by spoofing the user interface. This could lead to users interacting with malicious content that appears to be a legitimate part of the browser or a trusted website, potentially resulting in the theft of sensitive information or unauthorized actions.
Technical details
A UI spoofing vulnerability exists in Google Chrome's CSS implementation. The flaw stems from an inappropriate implementation that allows a remote attacker to manipulate the browser's user interface via a specially crafted HTML page. An attacker could exploit this by hosting a malicious website and enticing a user to visit it. Successful exploitation allows the attacker to misrepresent UI elements, potentially leading to phishing or other social engineering attacks. The issue is resolved in Google Chrome version 150.0.7871.47 for Windows and Mac, and 150.0.7871.46 for Linux.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: advisory
- 2026-06-30: patched